pm-close-acceptance-signoff
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted external data such as project context files (.agents/project-context.md), criteria, and evidence logs. This ingestion surface creates a risk of indirect prompt injection if the source data contains malicious instructions.
- Ingestion points: .agents/project-context.md and various project documentation sources.
- Boundary markers: Absent; there are no instructions to the agent to treat external content as data only or to ignore embedded instructions.
- Capability inventory: Minimal; the skill generates a report but does not possess high-risk capabilities like network access, command execution, or file writing.
- Sanitization: Absent; the workflow does not include validation or sanitization steps for the external data ingested.
Audit Metadata